Explanation
Threat actors are using a POST Luxembourg phishing theme to collect credit card information.
The phishing mail leads the user to believe that a shipment is still waiting for instructions, and by clicking on the link the user is first redirected to a fake POST website.
On this page, the victim has to enter credit card information, such as the card holder, card number, expiration date and the visual cryptogram.
Once they have provided this information, they are redirected to another fake page where they are asked for an SMS code and the card pin.
Example